A Tabletop As Big As the World
Wendy Nather
NorthSec 2025 · Day 2 · Ville-Marie · Keynote
Overview
Wendy Nather, one of the most experienced incident response practitioners in the field, uses the NorthSec 2025 closing keynote to argue that tabletop exercises are systematically underdesigned — too narrow in scope, too polite in scenario construction, and too rarely stress-tested against the real conditions of a bad day. Drawing from decades of incident work, corporate security leadership, and large-scale multi-stakeholder exercises including geopolitical simulations, she delivers a dense, practical framework for making tabletops actually useful. ---

Key moments
- 6:32 Microsoft threat intel team lacked working PGP key
- 13:39 AWS per-object logging gap caused 6-week forensic delay
- 15:40 Blackbaud ransomware rippled to hundreds of nonprofits
- 20:40 PayPal team found hidden malware disable command in exercise
- 10:30 Chicago flood forced bank to carry servers down stairs
- 8:40 Agency found 15K unknown servers buried in contract text
- 31:40 Satellite hack tabletop exposes Kessler Syndrome policy gap
- 32:00 Students won by co-opting frightened hacktivists as allies
A Tabletop As Big As the World
Speaker: Wendy Nather
Conference: NorthSec 2025 — May 15–16, 2025, Marché Bonsecours, Montreal
Watch on YouTube: https://www.youtube.com/watch?v=pq0NMN9HHOY
Reading time: ~9 minutes
TL;DR
Wendy Nather, one of the most experienced incident response practitioners in the field, uses the NorthSec 2025 closing keynote to argue that tabletop exercises are systematically underdesigned — too narrow in scope, too polite in scenario construction, and too rarely stress-tested against the real conditions of a bad day. Drawing from decades of incident work, corporate security leadership, and large-scale multi-stakeholder exercises including geopolitical simulations, she delivers a dense, practical framework for making tabletops actually useful.
Introduction
Most tabletop exercises replay known failure modes. They test whether the right people know about the incident response plan, whether the runbooks are current, and whether communication chains function as documented. What they rarely test is the chaos that attends real incidents: the key decision-maker unreachable, the logging tier too low to support forensics, the procurement process that takes weeks for tools needed in hours, and the third-party provider three layers deep in the supply chain whose ransomware event just cascaded into the organization's production environment.
Wendy Nather's Day 2 keynote at NorthSec 2025 addresses this gap directly. Her talk spans both the mechanics of well-designed tabletop exercises and the lessons learned from building exercises at geopolitical scale — simulations involving students from law, international relations, and policy disciplines alongside cybersecurity practitioners, stress-testing responses to scenarios that blend nation-state actors with cascading infrastructure failures. The register is practiced and direct; the anecdotes are specific and credible; the advice is operational.
The Logging Gap Nobody Admits
Nather opens her operational section with a blunt assessment: organizations do not have the logging they would need for a forensic investigation. Not because they have not been told to enable it, but because enabling full forensic logging is expensive, politically contested, and rarely tested against a live incident requirement until it is too late.
▶ Watch: Logging deficits and forensic readiness (12:00)
She cites a case in which a large security vendor, breached through AWS, could not notify affected parties for six weeks because per-object logging had not been enabled in their S3 configuration. AWS required six weeks to produce per-object logs retroactively, scoped specifically to that tenant's data, before the organization could confirm what had been accessed and begin mandatory notification. The vendor was running workloads in us-east-1. The logs existed; they simply had not been retained at the required granularity.
The tabletop implication is direct: run a scenario in which your primary forensic data source is unavailable or insufficiently detailed, and determine in advance what the escalation path is — including who at cloud providers has the relationship to accelerate emergency log retrieval.
The Provider Relationship Problem
A recurring thread throughout the talk is the distinction between contractual obligations and operational reality. Nather argues that incident response requires relationships with providers that go well beyond what any contract specifies, and that those relationships need to be established before the incident, not during it.
▶ Watch: Providers, procurement, and relationships under pressure (2:00)
She gives a practical example involving threat intelligence sharing. Her recommendation: pre-approve template disclosures with legal counsel so that when an incident occurs, the legal review for a sharing request is already complete. The template has been vetted; fields requiring redaction have been identified in advance. This reduces a multi-day process to hours.
The same logic applies to MFA rollouts. During her tenure at Duo Security, Nather observed large enterprises rolling out MFA as an emergency response to an active breach — a process that should take weeks happening in days under duress. Planning for fast procurement, including identifying who has authority to approve emergency spend and which vendor contacts can accelerate delivery, is a tabletop scenario that rarely appears on exercise agendas.
Designing Scenarios That Actually Hurt
Nather's most distinctive contribution is her approach to scenario construction. She argues that tabletop scenarios should be built to cause discomfort — not to reassure participants that existing plans are adequate, but to surface the assumptions baked into those plans.
▶ Watch: Scenario design: chaos engineering for incident response (14:00)
She recommends several concrete techniques. First, remove a key decision-maker from the exercise: designate the CISO or incident commander as "unreachable — on vacation with no signal" and observe what happens to the decision chain. Some organizations have regulatory requirements to do exactly this (Swiss banking regulations, for instance, require key personnel to take extended leave without contact to surface fraud risks); the same principle applies to incident response resilience.
Second, run scenarios where the incident touches a third-party provider the organization has never had to engage. She references the Blackbaud ransomware incident, in which a single platform serving nonprofit organizations generated cascading exposure for as many as a thousand downstream organizations — most of which had no direct contract with Blackbaud and had never heard the company's name before the breach.
Third, introduce infrastructure failure as a secondary effect. Nather describes an organization that initiated a mandatory password reset during an incident, only to have the authentication infrastructure collapse under the load — converting a containment action into a denial-of-service event. She also recounts her own experience as a bank employee during the 1992 Chicago flood, when a tunnel failure knocked out basement power across the Loop and teams rebuilt production backbone in New York and a Chicago suburb while physically carrying Sun4 servers down eleven flights of stairs in the dark.
Role-Specific Awareness and the Intelligence Value of SREs
Research Nather conducted with the Cyentia Institute during her time at Cisco produced a finding with direct tabletop implications: organizations that conducted role-specific incident response awareness training performed measurably better in actual incidents than those that relied on generic security awareness content.
▶ Watch: Role-specific training and the Cyentia research findings (6:00)
The practical consequence is that tabletop exercises should be designed with role-specific injects — scenarios where the legal team, the SRE organization, and the communications function are each receiving information appropriate to their domain and making decisions within their lanes. SREs in particular represent an underutilized source of early threat intelligence: they see anomalous infrastructure behavior before security tools alert, and they are far more likely than average employees to recognize that something is wrong and escalate appropriately — if they have been trained that escalating this kind of observation is part of their job.
Nather also flags secure communications as a tabletop scenario that sounds trivial and consistently fails in practice. She describes attempting to send threat intelligence to Microsoft's own threat intel team and being unable to obtain a working PGP key. In a separate incident, she had to route communication to a CISO she had never met through a LinkedIn contact, and ultimately transmit sensitive forensic data via fax — chosen because the adversary's access to the organization's communication channels was unknown and a random fax machine was the most plausible out-of-band channel available.
Tabletops at Geopolitical Scale
The second half of the talk turns to exercises Nather has designed at a scale well beyond the typical corporate incident. She describes multi-stakeholder simulations involving participants from law, international relations, and policy disciplines alongside cybersecurity professionals — exercises where the threat actors are nation-state level, the cascading effects cross jurisdictional boundaries, and the decisions being tested involve international law and diplomatic communication as much as technical response.
▶ Watch: Designing large-scale geopolitical tabletop exercises (16:00)
The design challenge in these exercises is that participants arrive with very different vocabularies and very different assumptions about what "response" means. A law student and a security engineer may be looking at the same incident from frameworks that do not readily translate into each other. Building exercises that force that translation — requiring legal participants to make technical decisions and requiring technical participants to articulate their reasoning in policy terms — surfaces gaps that single-discipline exercises cannot reach.
The lesson for corporate tabletops is structural: the more disciplines represented in the exercise, the more accurately it mirrors the actual conditions of a real incident, where the CISO is not the only decision-maker and where legal, HR, communications, and executive leadership each have veto power over actions the security team considers obvious.
Notable Quotes
"I can almost guarantee you that you will not have the level of logging that you need for forensics. It won't have been turned on by default."
"It took six weeks for AWS to get the logs for them — just for them, at a per-object level — until they could make sure that they really did have this data accessed, and then they could announce."
"What if it's this person who's an insider? How would we handle that? Roll some dice."
"Why should the red team have all the fun? You know your business. You know how bad things can get. Let's have some fun and play with it."
"Don't be too surprised. You can discover things like this when you're doing tabletops." — after describing an agency employee who found two acres of unknown data center in a third-party contract
Key Takeaways
- Logging gaps are structural and predictable. Forensic-grade logging is almost never enabled by default. Tabletops should include scenarios where primary forensic data is unavailable and the organization must navigate emergency retrieval from cloud providers with whom relationships have not been established in advance.
- Pre-approve disclosure templates. Threat intelligence sharing can be pre-authorized in template form before an incident. Legal review of a generic template eliminates the multi-day delay of per-incident legal approval during a breach.
- Remove the key decision-maker. Running exercises without the primary incident commander reveals cascading dependencies and single points of failure in the decision chain that no amount of documentation surfaces.
- Role-specific training outperforms generic awareness. Organizations that train personnel in how incidents look from their specific function — SRE, legal, communications, HR — respond measurably better than those relying on generalized security awareness programs.
- Third-tier providers are now part of the incident surface. The Blackbaud incident demonstrated that cascading breach impact can reach organizations that have no direct contractual relationship with the compromised entity. Tabletops should include scenarios where the initial vector is a provider's provider.
- Infrastructure can fail during containment. Mandatory password resets, agent deployments, and other containment actions can generate secondary failures. Exercises should test degraded-state operations explicitly.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Wendy Nather uses the closing keynote to deliver a practical framework for designing tabletop exercises that actually stress-test assumptions rather than confirm existing plans. Key contributions: the logging-gap section (illustrated by a real 6-week AWS log retrieval delay during an active breach), the 'remove the key decision-maker' technique, role-specific vs. generic training research from Cyentia, and lessons from geopolitical-scale multi-disciplinary exercises.
Heather Calloway (CISO) — MUST SEE
Wendy Nather is describing the gap between the incident response plan organizations write and the incident response capability they actually have. Those are not the same thing, and the gap only becomes visible under conditions that tabletops rarely reproduce. This talk is a checklist for every CISO who has run a tabletop and walked away feeling good about the result.